← Back

Colibri Firmware

colibri_firmware

Vendor: Franklinfueling • 3 CVEs

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Franklinfueling
1Colibri Firmware
Nov 21, 2024
Nov 27, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
The discontinued FFS Colibri product allows a remote user to access files on the system including files containing login credentials for other users.
1Franklinfueling
1Colibri Firmware
Apr 24, 2025
Dec 5, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Franklin Fueling System FFS Colibri 1.9.22.8925 is affected by: File system overwrite. The impact is: File system rewrite (remote). ¶¶ An attacker can overwrite system files like [system.conf] and [passwd], this occurs b...Show more
Franklin Fueling System FFS Colibri 1.9.22.8925 is affected by: File system overwrite. The impact is: File system rewrite (remote). ¶¶ An attacker can overwrite system files like [system.conf] and [passwd], this occurs because the insecure usage of "fopen" system function with the mode "wb" which allows overwriting file if exists. Overwriting files such as passwd, allows an attacker to escalate his privileges by planting backdoor user with root privilege or change root password.Show less
1Franklinfueling
1Colibri Firmware
Nov 21, 2024
Apr 7, 2022
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Insecure handling of a download function leads to disclosure of internal files due to path traversal with root privileges in Franklin Fueling Systems Colibri Controller Module 1.8.19.8580.